We're sunsetting PodQuest on 2025-07-28. Thank you for your support!
Export Podcast Subscriptions
cover of episode Penetration Tests: useful, pointless, harmful, required, ineffective? - Phillip Wylie - ESW #398

Penetration Tests: useful, pointless, harmful, required, ineffective? - Phillip Wylie - ESW #398

2025/3/16
logo of podcast Security Weekly Podcast Network (Video)

Security Weekly Podcast Network (Video)

Shownotes Transcript

Penetration tests are probably the most common and recognized cybersecurity consulting services. Nearly every business above a certain size has had at least one pentest by an external firm.

Here's the thing, though - the average ransomware attack looks an awful lot like the bog standard pentest we've all been purchasing or delivering for years. Yet thousands of orgs every year fall victim to these attacks. What's going on here? Why are we so bad at stopping the very thing we've been training against for so long?

This Interview with Phillip Wylie will provide some insight into this! Spoiler: a lot of the issues we had 10, even 15 years ago remain today.

Segment resources:

  • Phillip's talk, Optimal Offensive Security Programs) from Dia de los Hackers last fall

Show Notes: https://securityweekly.com/esw-398)